SERVICES — INNOVATION AXIS
AI, cybersecurity and regulation: they aren't governed separately
Italian manufacturing companies are facing three simultaneous transformations: adopting AI in processes and products, complying with new cybersecurity regulations (AI Act, NIS2, CRA), and innovating faster than before. Those who manage innovation must understand the regulatory constraints. Those who oversee cybersecurity must understand where AI creates new risks. Those who lead management must know which decisions they cannot delegate.
Forge is the training path that tackles these three transformations in an integrated way — with language accessible to management and concrete cases from Italian manufacturing.
THE STRUCTURE
A common foundation, then two variants for different targets
The common foundation gives the whole team an integrated view of AI and cyber risk — the shared language to decide together. The two variants deep-dive into the perspective of those who design the product (Variant A) and those who govern the transformation (Variant B). The two variants are cumulative: many companies bring both targets through the common foundation, then split them.
COMMON FOUNDATION — MANDATORY
The changing picture: three themes, one language
Three modules for all Forge participants — management and technical staff together. The goal is not to create experts, but to build common ground for deciding: what's changing, where the risks are, how to read an assessment without being a technician.
HYB-01 · 4 HOURS
AI, Cybersecurity and Regulation: the Changing Picture
Target: Management, board, entrepreneurs. Sellable on its own as an executive awareness session.
- →The moment we are living: convergence of AI, cybersecurity and EU regulation
- →AI Act: what it is, who it concerns, what it requires — in 45 minutes without jargon
- →NIS2 and CRA: why they change management's responsibilities, not just IT's
- →IEC 62443 and its role in the CRA: the standard becoming mandatory for manufacturing
- →The decisions regulations impose on the CEO over the next 24 months
- →How to read combined AI + cyber risk without being a technician
Workshop — what you build: A personal exposure map — the regulations relevant to your organization, with the first 3 urgent decisions to bring to management.
HYB-02 · 4 HOURS
Innovating with AI Without Creating Risks
Target: Management, innovation managers, function heads.
- →The AI innovation cycle: from idea to deployment, where the risks arise
- →Regulatory risks of AI in the company: AI Act, liability, audit trail
- →Operational risks: dependency, output quality, error handling
- →Reputational risks: bias, transparency, customer and employee trust
- →The role of the UNI 11814 Innovation Manager in governing company AI
- →AI governance: minimal policy, roles, approval processes
Workshop — what you build: An AI governance canvas — a map of AI use cases in use or under evaluation, with associated risks and priority governance measures.
HYB-03 · 4 HOURS
Reading Risk: AI and Cyber Together
Target: Management, leadership team, quality and safety managers.
- →Why AI and cyber risks amplify each other: concrete scenarios
- →The integrated risk model: assets, threats, impacts, probability
- →How to read the results of an AI or cybersecurity assessment without being a technician
- →Risk indicators for management: what to monitor, how to interpret it
- →Cyber insurance: how AI and OT risk change policies
- →How to communicate integrated risk to the board and stakeholders
Workshop — what you build: A simplified risk dashboard — a map of priority AI and cyber risks with monitoring indicators and alert thresholds for management.
VARIANT A — PRODUCT
For those who design: AI in the development cycle, CRA and IEC 62443 in practice
The design decisions that determine CRA compliance can't be delegated to legal or IT. And AI embedded in the product brings additional obligations that don't appear in current manuals. This variant is for those who have to make those decisions. Target: R&D teams, product managers, CTOs of companies with connected products or industrial machinery.
HYB-A1 · 4 HOURS
AI in the Product Development Cycle
- →AI in product design: generative design, simulation, optimization
- →AI in testing and quality: automation, anomaly detection, predictive
- →AI embedded in the product: opportunities, architectures, constraints
- →What changes with the CRA when the product incorporates AI: additional obligations
- →AI Act and high-risk products: classification, requirements, documentation
- →Real cases from Italian manufacturing: where AI creates value in the product today
Workshop — what you build: An AI opportunity map for your product or product line — identifying the most promising AI use cases, their associated regulatory constraints and an exploration priority.
HYB-A2 · 4 HOURS
CRA and IEC 62443 for Designers
- →CRA in practice for designers: essential requirements, documentation, deadlines
- →IEC 62443-4-1 and 4-2: what they ask of the development team — without reading the standard
- →Secure by design: the 10 design decisions that make the difference
- →Vulnerability handling and SBOM: concrete obligations and accessible tools
- →How to integrate CRA requirements into the existing development process without overturning everything
- →The software supply chain: responsibilities toward vendors and customers
Workshop — what you build: A CRA readiness checklist for a real product of the organization — identifying the main gaps and the priority adaptation actions.
VARIANT B — ORGANIZATION
For those who govern: AI Act and NIS2 in practice, a culture of secure innovation
The AI Act, NIS2 and CRA aren't an IT problem. They change management's responsibilities, investment decisions, vendor contracts. This variant is for those who carry those responsibilities. Target: CEOs, entrepreneurs, leadership teams.
HYB-B1 · 4 HOURS
AI Act and NIS2 in Practice: Management Decisions
- →AI Act: the decisions that belong to the CEO, not the technician
- →NIS2: governance obligations, incident notification, top-management responsibility
- →CRA: what changes for those who sell connected products in Europe
- →How to build a regulatory adaptation plan without dedicated resources
- →Vendors and supply chain: extended responsibility and contracts to update
- →Sanctions and legal risks: what happens if you don't comply
Workshop — what you build: A concise compliance action plan — a list of urgent decisions to make over the next 90 days, with priorities, responsibilities and required resources.
HYB-B2 · 4 HOURS
Building a Culture of Secure Innovation
- →Why company culture determines the success or failure of AI adoption
- →Change management for AI: resistance, expectations, internal communication
- →Training people: how to build an AI upskilling plan by function
- →Company AI policy: how to build it, enforce it and update it
- →The manager's role as a promoter of secure innovation
- →Real cases: manufacturing companies that integrated AI successfully
Workshop — what you build: An AI change management plan — identifying the main sources of resistance, communication actions, a minimal training plan for your team.
INTENSIVE WORKSHOPS
Leave with a roadmap, not just with skills
The intensive workshops are separate operational sessions — addable to any Forge path — in which the group builds a real document over the course of the day, ready to be brought to a leadership meeting. You don't discuss strategy: you write it.
WORKSHOP A · HALF-DAY OR FULL-DAY AI-Ready and CRA-Compliant Product Roadmap
For whom: R&D teams, product managers, CTOs — after Forge Product or as a standalone session.
Half-day structure (4 hours)
- Briefing: current product state and innovation goals
- Strategic canvas: mapping AI opportunities × CRA requirements
- Prioritization: impact / effort / regulatory risk matrix
- Output and next steps
Full-day structure (8 hours)
- Morning: in-depth diagnosis — product state, regulatory gaps, AI opportunities
- Afternoon: roadmap construction — milestones, responsibilities, estimated investments, KPIs
- Closing: presentation to management and validation
What you receive (full-day): A complete 12–18 month roadmap for the product's evolution toward AI integration and CRA/IEC 62443 compliance — with milestones, responsibilities, estimated investments and progress indicators. Ready to be brought to a leadership meeting.
WORKSHOP B · HALF-DAY OR FULL-DAY Secure Digital Transformation Plan
For whom: CEOs, leadership teams — after Forge Leadership or as a session for the management team.
Half-day structure (4 hours)
- Briefing: current state, transformation goals, constraints
- Strategic canvas: AI opportunities × cyber risks × regulatory obligations
- Prioritization: impact / urgency / feasibility matrix
- Output and next steps
Full-day structure (8 hours)
- Morning: diagnosis — where we stand on AI, cyber and regulation; gaps against goals
- Afternoon: plan — priority initiatives, milestones, estimated budget, responsibilities, KPIs
- Closing: presentation and validation with the leadership team
What you receive (full-day): A 12–18 month secure digital transformation plan — with integrated AI, cybersecurity and compliance initiatives, milestones, responsibilities, estimated investments and progress indicators. Ready to be presented to the board or investors.
The pre-workshop briefing (1 hour) is included. The workshops produce better outputs when participants arrive with material: product specs or technology roadmap for Variant A; strategic plan or transformation goals for Variant B.
AI GOVERNANCE — ISO 42001
The next step for those who want to structure AI formally
The ISO 42001 modules are the natural completion of any Forge path for those who want to go beyond awareness and build a structured AI Management System — compliant with ISO 42001 and aligned with the AI Act. They are cross-cutting across both variants.
ISO42-01 · 1 MODULE · 4 HOURS
Introduction to ISO 42001
Structure of the standard, relationship with the AI Act and other management standards (ISO 9001, ISO 27001), how a manufacturing SME can approach it. Sellable on its own as an awareness session.
Workshop: each participant builds an AI organizational context map — identifying existing or planned AI uses, main risks, governance areas to oversee.
ISO42-02 · 1 MODULE · 4 HOURS
Implementing an AI Management System
Gap analysis, company AI policy, AI risk management, mandatory documentation, the path toward certification and what's needed to reach certification.
Workshop: each participant starts an ISO 42001 gap analysis with a 90-day action plan.
The ISO 42001 modules are taught by Alberto Scarpa, certified ISO/IEC 42001 Lead Implementer (PECB), member of the UNI CT 533 Technical Committee — Artificial Intelligence.
PATHS
Six starting combinations
Every path is customizable. The 1–2 hour pre-course briefing (included) calibrates the content to the company's specific context.
Executive Awareness
HYB-01
For management teams, boards, entrepreneurs. A standalone awareness session on the AI + cybersecurity regulatory picture. Sellable as a single intervention at company conventions or leadership meetings.
Forge Essentials
HYB-01 + HYB-02 + HYB-03
The complete common foundation. The team gains an integrated view of AI, cybersecurity and innovation — with practical tools to read and communicate risk.
Forge Product
HYB-01 + HYB-02 + HYB-03 + HYB-A1 + HYB-A2
For R&D teams and product managers. From the general picture to the design decisions that determine CRA and IEC 62443 compliance.
Forge Product + Workshop
Forge Product + Workshop A
For R&D teams that want to leave with an operational roadmap already presentable.
Forge Leadership
HYB-01 + HYB-02 + HYB-03 + HYB-B1 + HYB-B2
For CEOs and leadership teams. From the regulatory picture to management decisions, up to the culture of secure innovation.
Forge Leadership + Workshop
Forge Leadership + Workshop B
For leadership teams that want to leave with an operational plan already validated.
Custom — from 2 modules. A free combination for specific needs.
GROUPS up to 12 (10 for workshops) · FORMAT in person or remote · LANGUAGE Italian or English · MATERIALS slides, canvases and checklists included · BRIEFING pre-course included
AFTER FORGE
Training prepares. Assessment measures. Oversight maintains.
Whoever takes part in Forge gains the language and conceptual framework to start an assessment or consulting path with full awareness. It's not required: each level stands alone. But those who do it, do it on concrete ground.
Where do you want to start?
If you're not sure which Forge path is the right one, the Regulatory Spark is for this: 45 minutes to understand the starting point on concrete ground, not on generic slides. If you already have a clear idea, write to me for the detailed program.
Book the Regulatory Spark — free